ITSI MCP tools

ITSI 5.0.1 provides read-oriented access to ITSI episode investigation context through Splunk MCP Server. Use these tools to retrieve episode details, impacted services and KPIs, related entities, external links, similar episodes, and stored summarization from authorized MCP-compatible clients.

Available ITSI MCP tools

The following ITSI tools support investigation workflows. ITSI 5.0.1 ships these predefined tool definitions in tools.conf; customers do not need to create the tool definitions manually.

Tool Purpose Typical use
SA-ITOA_get_episodes List and filter ITSI episodes. Find active or recent episodes by lookback, severity, count, and sort order.
SA-ITOA_get_episode_details Retrieve metadata for a specific episode. Review title, status, severity, owner, duration, event count, and instructions.
SA-ITOA_get_impacted_objects Retrieve affected services, KPIs, and entities. Understand blast radius and prioritize investigation areas.
SA-ITOA_get_external_links Retrieve linked external references. Find related Jira tickets, ServiceNow incidents, runbooks, or reference URLs.
SA-ITOA_get_similar_episodes Retrieve similar historical episodes. Identify recurring patterns and previous resolution paths.
SA-ITOA_get_episode_summarization Retrieve stored episode summarization. Review AI-generated summary, timeline, impact, and suspected root causes when Event iQ Diagnose is enabled.